summaryrefslogtreecommitdiff
path: root/crates/tor-proto/src/crypto
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'virtual_hop' into 'main'Nick Mathewson2023-05-181-24/+93
|\ | | | | | | | | | | | | tor-proto: Add support for extending circuits through virtual hops. Closes #726 See merge request tpo/core/arti!1191
| * proto: Try to improve the documentation in crypto/cell.rsNick Mathewson2023-05-181-24/+86
| |
| * tor-proto: Code to construct crypto layers for virtual hops.Nick Mathewson2023-05-181-0/+7
| | | | | | | | | | This is fairly straightforward, thanks to our existing design work on this code.
* | hs_ntor: several documentation cleanups.Nick Mathewson2023-05-171-6/+14
| |
* | hs_ntor: make encrypt_and_mac take a typed public keyNick Mathewson2023-05-171-10/+6
| | | | | | | | This is still not the most beautiful interface, but it'll do for now.
* | hs_ntor: remove the last lingering AsRef<[u8]>Nick Mathewson2023-05-171-7/+7
| |
* | hs_ntor: Add a test vector case extracted from C tor.Nick Mathewson2023-05-171-0/+104
| |
* | hs_ntor: Calculate MAC on introduce1 message correctly.Nick Mathewson2023-05-171-3/+12
| | | | | | | | | | | | There were two bugs here that made the behavior unlike that of C tor: we had swapped the MAC inputs, and we had forgotten to include the public key X in the input.
* | hs_ntor: Make internal no-rng variants of the handshake functions.Nick Mathewson2023-05-171-2/+25
| | | | | | | | We'll want these so we can implement some test vectors.
* | hs_ntor: Move extra data outside of the "input" fields.Nick Mathewson2023-05-171-59/+33
| | | | | | | | | | | | | | I think that these Input structs had been defined so that we could use hs_ntor interchangeably with other handshakes. The trouble is, though, that it doesn't really work like any other handshakes we have.
* | hs_ntor: Use MAC implementation from tor-hscryptoNick Mathewson2023-05-171-35/+16
| | | | | | | | | | | | Note that some of the invocations for this function seem to put the key and the message in a questionable order. But that's a thing to figure out later, while debugging.
* | hs_ntor: Use correct PK types from tor_hscrypto.Nick Mathewson2023-05-171-20/+24
| |
* | hs_ntor: Use Subcredential type from tor-hscryptoNick Mathewson2023-05-171-4/+3
|/
* Use non-deprecated *Secret::random_from_rng.Nick Mathewson2023-05-133-13/+13
| | | | The `new` function is deprecated in x25519-dalek 2.0.0-rc.2
* Rename onion-* cargo features to hs-* in tor-* cratesIan Jackson2023-02-282-2/+2
| | | | Fixes #756
* tor-cell: Refactor relay cells to copy much lessNick Mathewson2023-02-151-18/+8
| | | | | | | | | | | | | We now manipulate raw relay cell bodies as (an alias for) `Box<[u8;509]>` rather than as (an alias for) `[u8;509]`. This enables us to do much less copying. It will become more important soon, as we defer parsing relay cell bodies even longer. Related to #7. We also use SliceWriter to avoid allocating a Vec<> for every relay message we want to encode, and instead encode directly into the cell.
* Allow clippy::unchecked_duration_subtraction in testsNick Mathewson2023-01-275-0/+5
| | | | | This panics on error, and we're fine with a panic on misbehavior in tests.
* tor-proto: Expose support for doing onion service handshakesNick Mathewson2023-01-172-17/+18
| | | | | | This is a little tricky, but I think that we're not actually exposing too much here. I expect we'll need to tweak this stuff between now and our final version.
* tor-proto: Rename "hs" experimental feature to "onion-common"Nick Mathewson2023-01-171-1/+1
| | | | (For consistency with other crates)
* test lint blocks: Add many many automaticallyIan Jackson2022-12-124-0/+33
| | | | | This is precisely the result of running the rune in maint/adhoc-add-lint-blocks.
* test lint blocks: Do some semi-manuallyIan Jackson2022-12-121-1/+9
| | | | | | | This is the hunks from running the rune in maint/adhoc-add-lint-blocks but which require some subsequent manual fixup: usually, deleting now-superfluous outer allows, but in some cases manually putting back lints that the adhoc script deleted.
* Fix a bunch of "needless borrow" warnings on nightlyNick Mathewson2022-11-181-2/+2
| | | | | It looks like, despite a few false starts, they've got this warning right; there weren't any false positives.
* fix clippy::needless_borrowtrinity-1686a2022-09-101-1/+1
|
* Merge branch 'zeroize' into 'main'Nick Mathewson2022-08-047-75/+90
|\ | | | | | | | | | | | | Revise our handling of the zeroize trait Closes #254 See merge request tpo/core/arti!655
| * tor-proto: Use correct SecretBuf in handshakes.Nick Mathewson2022-08-014-17/+27
| | | | | | | | | | | | | | | | Everything that is a secret encryption key, or an input that is used to produce a secret encryption key, has to get zeroized. And that's all! Closes #254.
| * tor-proto: Replace SecretBytes with SecretBuf.Nick Mathewson2022-08-017-60/+65
| | | | | | | | | | | | | | | | | | | | This does not yet make sure that `SecretBuf` is used where it _should_ be, but at least it ensures that most uses of `SecretBytes` will indeed act as intended, and make sure that whatever they contain is zeroized. It requires some corresponding changes to method calls for correctness and type conformance.
* | Rename `.inc` and other included files to end in `.rs`eta2022-07-261-1/+1
|/ | | | | | | | | | | | | In order to mitigate syntax highlighting issues and a rust-analyzer bug (https://github.com/rust-analyzer/rust-analyzer/issues/10178), rename files that are included with the `include!` macro to have a `.rs` extension. Make sure the included files are outside `src/`, in order to not confuse humans and automated editing tools that might mistake them for valid Rust modules. fixes arti#381
* tor-proto: Stop using write_infallible in handshake code.Nick Mathewson2022-07-113-138/+174
| | | | | | | | This change was a bit annoying, since most of this code _can't_ fail, and so the only reasonable response is to wrap the input in an internal error... except for one case where we're actually encoding a caller-provided message, so we _do_ want to wrap the EncodeError from tor_bytes.
* Remove "write_and_consume_infallible".Nick Mathewson2022-07-111-7/+12
| | | | | | There were only a few of these. Removing it required porting everything to use `write_and_consume` instead, and handling its (potential) errors.
* Rename "write" methods on tor-bytes to "write_infallible".Nick Mathewson2022-07-113-112/+112
| | | | | | | | | | | | | | | This comprises four renames: ``` write_onto -> write_onto_infallible write_into -> write_into_infallible write -> write_infallible writer_and_consume -> write_and_consume_infallible. ``` The rest of this branch will be concerned with replacing these `_infallible` methods with ones that return a `Result`. This is part of #513.
* Implement a higher-level API for the ntor v3 handshakeeta2022-07-081-23/+162
| | | | | | | | | | | | | | | | | | | This implements a higher-level API for the ntor v3 handshake, in line with that exposed by the ntor handshake. It does not, however, use the existing `ClientHandshake` trait, due to fundamental differences in the handshakes (namely, that the v3 handshake can include some additional extra extension data). Currently, the higher-level API assumes circuit extension, and copies the (undocumented!) magic verification string from c-tor that indicates this usage. A rudimentary set of functions for serializing and deserializing extensions to be sent with the handshake is also included, implementing the protocol in proposal 332 § A.2. Currently, it only implements the congestion control extensions specified in proposal 324 § 10.3. part of arti#88
* Update `rsa` dependency (and use `x25519-dalek` prerelease)eta2022-07-061-6/+5
| | | | | | | | | | | | | | - arti#448 and arti!607 highlight an issue with upgrading `rsa`: namely, the `x25519-dalek` version previously used has a hard dependency on `zeroize` 1.3, which creates a dependency conflict. - However, `x25519-dalek` version `2.0.0-pre.1` relaxes this dependency. Reviewing the changelogs, it doesn't look like that version is substantially different from the current one at all, so it should be safe to use despite the "prerelease" tag. - The new `x25519-dalek` version also bumps `rand_core`, which means we don't have to use the RNG compat wrapper in `tor-llcrypto` as much. closes arti#448
* tor-proto: split and elaborate tor_bytes::Error instancesNick Mathewson2022-06-233-9/+28
| | | | | | | | | Some of these were for decoding particular objects (we now say what kind of objects), and some were unrelated tor_cert errors that for some reason we had shoved into a tor_bytes::Error. There is now a separate tor_cert::CertError type, independent from tor_cert's use of `tor_bytes::Error` for parsing errors.
* tor-proto: clean up error names and messagesNick Mathewson2022-06-236-17/+17
| | | | | This avoids adding additional information for now; that will come on the next commits.
* Use testing_rng() in tests throughout our crates.Nick Mathewson2022-06-025-7/+12
| | | | | | This only affects uses of thread_rng(), and affects them all more or less indiscriminately. One test does not work with ARTI_TEST_PRNG=deterministic; the next commit will fix it.
* Upgrade to AES 0.8Nick Mathewson2022-04-263-4/+4
| | | | | | | | Now that we require Rust 1.56, we can upgrade to AES 0.8. This forces us to have some slight API changes. We require cipher 0.4.1, not cipher 0.4.0, since 0.4.0 has compatibility issues with Rust 1.56.
* squash! Bump every crate's edition to 2021.Nick Mathewson2022-04-252-3/+0
| | | | | Remove all `use` statements for `TryFrom` and `TryInto`. These are now redundant in Rust 2021.
* tor-proto: Rename BadHandshake to BadCircHandshakeNick Mathewson2022-02-234-6/+6
| | | | (We'll have a BadChanHandshake soon.)
* Eliminate RequestedResourceAbsent kind.Nick Mathewson2022-02-224-17/+44
| | | | | | | | There was only one use of this, and it was in as-yet-unused relay-only code. Removing this type required refactoring the relay onion handshake code to use its own error type, which is probably clever anyway.
* Update tor-proto errors to latest API.Nick Mathewson2022-02-151-1/+1
|
* tor-proto: use InternalError for internal errors.Nick Mathewson2022-02-152-4/+12
|
* Remove many needless borrows and slicesIan Jackson2022-02-021-4/+4
| | | | | | | Found via clippy::needless_borrow. In some cases I removed needless `[..]` too. See also: needless_borrow suggestion doesn't go far enough https://github.com/rust-lang/rust-clippy/issues/8389
* prefer 'unwrap_or_default' to manual constructorDaniel Eades2022-01-011-1/+1
|
* Merge remote-tracking branch 'origin/mr/180'Nick Mathewson2021-12-081-11/+10
|\
| * In CryptInit, return a Result in initialize()Neel Chauhan2021-12-081-11/+10
| |
* | Upgrade to digest v0.10.0Nick Mathewson2021-12-072-4/+4
|/ | | | | We generally try to track the latest rust-crypto traits when we can: fortunately, this upgrade didn't break much, considering.
* Remove some XXXs about zeroizing from tor-proto.Nick Mathewson2021-12-071-2/+0
| | | | There is now a ticket about this issue in general, at arti#254.
* Resolve roughly half of the XXXXs.Nick Mathewson2021-12-064-8/+11
| | | | | | | | We want to only use TODO in the codebase for non-blockers, and open tickets for anything that is a bigger blocker than a TODO. These XXXXs seem like definite non-blockers to me. Part of arti#231.
* add constructorsdagon2021-11-301-17/+53
|
* add semicolons if nothing returnedDaniel Eades2021-11-251-1/+1
|